Security at GrowSurf

Last updated: August 4, 2026

GrowSurf, Inc. is committed to data security. Here is how we protect and handle private and sensitive data:

  • Data processing: GrowSurf processes data only to fulfill its obligations as related to the Services outlined in our Terms of Service. All personal information for GrowSurf users and participants are shared to the minimal extent. Please see section HOW AND WHY WE USE YOUR PERSONAL INFORMATION on our Privacy Policy
  • Data storing (PII or otherwise) with third party vendors: Please see section PERSONAL INFORMATION WE COLLECT ABOUT USERS AND PARTICIPANTS on our Privacy Policy
  • Data sharing (PII or otherwise) with third-party vendors: We share data with service providers only as needed to provide, secure, support, and improve the Services. Our current subprocessors and their purposes are listed on the GrowSurf Compliance Portal.
  • Data encrypted in transit: We encrypt all data over the HTTPS network protocol.
  • Data encrypted at rest: Customer data stored in our primary databases and backups is encrypted at rest. Sensitive integration credentials and secrets that must be stored are also encrypted at rest using industry-standard cryptography.
  • Tax form data (W-9/W-8 and 1099 filing): When you use GrowSurf's tax documentation features, W-9 and W-8 tax forms are collected through an IRS-authorized e-file partner. GrowSurf never stores participants' full Social Security numbers or tax IDs — that sensitive data is held securely by the partner, which may also perform IRS TIN matching. GrowSurf stores only the last four digits and the limited status and filing metadata needed to hold payouts, prepare 1099 filings, and meet legal recordkeeping requirements.
  • Data storage: Our production application infrastructure and managed MongoDB are hosted in DigitalOcean's SFO2 datacenter (San Francisco, United States). Firebase Realtime Database is hosted in Google Cloud's us-central1 region (Iowa, United States). Other service providers may process data in the locations disclosed on our current subprocessor list.
  • Data security: GrowSurf uses firewalls, IP allowlists, and network load balancing to protect and operate the Services. DigitalOcean and Google Cloud Platform provide cloud infrastructure, Cloudflare helps protect and deliver network traffic, and SigNoz provides application monitoring and logging.
  • Account audit log: Every GrowSurf account has an audit log that records what changed in the account over the last 90 days and who changed it — team member and access changes, program and reward edits, participant, commission and payout actions, integration connections, and API key activity. Changes made by your team are shown separately from automatic activity. Only the account owner and team admins can view it, and the log is read-only.
  • Backups: We maintain daily backups for disaster recovery. DigitalOcean managed MongoDB backups are retained for seven days, and Firebase Realtime Database export backups are retained for up to 30 days. When data is deleted from active systems, residual backup copies are placed beyond use and expire under the applicable backup cycle.
  • Business Continuity Process: Our internal Business Continuity Process (BCP) outlines protocols in the event of a disruption to normal operations.
  • Disaster Recovery Process: Our internal Disaster Recovery Process (DRP) outlines protocols to restore data in the event of disasters.
  • Data breaches: Our internal GDPR and CCPA compliance processes cover protocols for data breaches, user policies, and more.
  • Organizational policies: Our internal IT Procedures and Security Policies cover general internal protocols, password and security/network policies for GrowSurf employees, including handling sensitive customer data.

For dependency-specific controls and verification limits, see our security advisories and OpenVEX statements.

If security compliance is a must-have for your organization, many GrowSurf self-service customers are able to require a manual opt-in checkbox for participants with a link to GrowSurf's Terms of Service and Privacy Policy in order to partake in the referral program.

Please note, we only accommodate security questionnaire requests, modified DPA requests, or any other legal/vendor requirements for customers on our annual custom plans. If you have bespoke legal and compliance needs, please get in touch with sales.